Walkthrough
Anatomy of a Ransomware Attack
Updated
Ransomware does not begin with a splash screen. It begins with a file someone in the firm was supposed to open — an invoice, a closing binder, a shipping PDF, a staffing roster. Within minutes a process can start, a foothold can hold, and the shared folders that keep a CPA, law, manufacturing, or care team working can lock. This page walks the first hour in four beats so you can see where a tested backup and a desk that answers change the ending. It is a walkthrough, not a scoreboard. Manage IT NY is a New York cybersecurity and managed IT partner. Call (631) 557-0440 when you want the practice to stay open.
Stage 00
Beat 00
Minute 0: the file lands
A closing binder, an invoice PDF, a packing slip. Someone opens what looks like the day's work. That is the start — not a movie lock screen. On a tax-week workstation, a matter share, a plant office PC, or a nurses' station, the first minute is ordinary. The question is whether the firm notices before the file becomes a process.
Beat 01
A process starts and holds a foothold
If the file was hostile, a process can start and stay. It often looks like software doing a job. Logging, endpoint controls, and a person who will pick up the phone are what turn this minute from “we will see” into “we are containing.” A ticket queue that replies tomorrow is not a foothold response.
Beat 02
Shares lock as encryption spreads
The next move is not one laptop. It is the share everyone uses — client files, drawings, charts, billing. Encryption that reaches the file server is what closes a practice for a week. Segmentation, backups that actually restore, and stopping the spread matter more than the font on a ransom note.
Beat 03
Backups and a 24/7 desk change the ending
The ending is not guaranteed. Immutable backups, a tested restore, MFA, and a desk that answers at 2 a.m. are what keep the practice open. Manage IT NY works that problem so a professional firm is not waiting on a national queue while the share stays locked.
Questions firms ask
Straight answers before the share locks.
- How fast can ransomware lock a professional firm?
- Once a hostile file runs, a foothold can form in minutes and encryption can reach a shared drive the same day. Speed depends on controls, how flat the network is, and whether anyone is watching. The first hour is when a live desk still changes the ending.
- If we have backups, are we safe?
- Backups help only if they restore. They need to be reachable when the production share is not, tested, and protected from the same account that just got encrypted. A backup that has never been restored is a hope, not a plan — and carriers ask for the proof.
- What should we do if someone opened a suspicious file?
- Take the workstation off the network, do not pay or reboot into a cleanup you have not planned, and call a partner who will contain first. Manage IT NY at (631) 557-0440 is a desk that answers — not a form that promises a ticket number.
Ready to stay open — and ready for the carrier.
Book a call about backups that restore, MFA and logging a carrier will accept, and a desk that answers when a file should not have been opened. This is insurance readiness and operations — not a scare reel.
